CVE Vulnerability Database

Search and browse 397,840 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-49386MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ...
CVE-2026-49385MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account...
CVE-2026-49384MEDIUM6.1In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49383LOW3.3In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49382HIGH7.8In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-49381MEDIUM4.8In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49380MEDIUM6.1In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49379MEDIUM6.5In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-49378MEDIUM4.3In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
CVE-2026-49377MEDIUM4.3In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49376MEDIUM6.5In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
CVE-2026-49375MEDIUM6.1In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49374HIGH7.6In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49373HIGH8.8In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49372HIGH7.5In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371HIGH8.2In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49370HIGH7.5In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49369MEDIUM4.3In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-49368MEDIUM5.4In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49367HIGH8.8In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49366HIGH7.8In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-47745MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie...
CVE-2026-47744CRITICAL9.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al...
CVE-2026-47742MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E...
CVE-2026-47741MEDIUM5.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ...